Prilex

lore

securityhacking

The Brazilian threat group active since 2014 that began with automated teller machine malware - jackpotting more than a thousand machines at one bank in a single 2016 incident and cloning some twenty-eight thousand cards - then rebuilt itself around point-of-sale systems.

Prilex is the clearest evidence that Brazilian crews were innovators rather than imitators. The point-of-sale generation works at the PIN pad protocol level rather than through higher-level interfaces, patches target software in real time, hooks system libraries, and generates cryptograms so that transactions on chip-and-PIN cards can be turned into fraudulent ones. It was also sold as a service. The capability profile - detailed knowledge of payment software and protocols - suggests insider understanding of the industry it attacked.

Also known as: atm jackpotting brasil, pos malware, ghost transactions, pinpad

All glossary entries